YAML Metadata Warning:empty or missing yaml metadata in repo card

Check out the documentation for more information.

modelscan-keras-compile-config-lambda-bypass

This repository contains a proof of concept for a scanner bypass in .keras model files.

Vulnerability

The open-source protectai/modelscan Keras logic only inspects serialized model layers.

That misses a second deserialization surface that Keras also loads from .keras archives:

  • compile_config

A malicious .keras file can hide a serialized dangerous __lambda__ inside the compiled loss configuration while keeping the model layers completely benign.

Keras still treats the lambda as unsafe and rejects it in safe_mode=True, but modelscan returns no findings because it never inspects compile_config.

Primary PoC

The main PoC file is:

  • artifacts/compile_lambda.keras

The payload is harmless. When the model is loaded unsafely and evaluated, it writes a local marker file at:

  • KERAS_COMPILE_MARKER.txt

Included Files

  • artifacts/compile_lambda.keras
  • artifacts/reproduce_output.txt
  • artifacts/sha256sums.txt
  • reproduce.py

Tested Environment

Reproduction

1. Verify the included PoC

Run:

KERAS_BACKEND=numpy python reproduce.py --modelscan-path /path/to/modelscan

If modelscan is already installed in your environment, --modelscan-path is optional.

Expected results:

  • top-level layer classes are InputLayer and Dense
  • the compile loss is serialized as __lambda__
  • safe_mode=True rejects the model as unsafe
  • safe_mode=False loads the model
  • model.evaluate(...) creates the marker file
  • modelscan helper returns []
  • modelscan helper scan path reports zero issues and zero errors

2. Rebuild the artifact from source logic

Run:

KERAS_BACKEND=numpy python reproduce.py --build --modelscan-path /path/to/modelscan

This regenerates artifacts/compile_lambda.keras and reruns the verification steps.

Observed Results

From artifacts/reproduce_output.txt:

  • top_level_layer_classes: ['InputLayer', 'Dense']
  • compile_loss_class: __lambda__
  • safe_mode=True rejects the model
  • safe_mode=False loads successfully
  • marker file is created during evaluation
  • modelscan_helper_operators: []
  • modelscan_helper_issue_count: 0
  • modelscan_helper_errors: 0

Impact

This is a practical scanner bypass for a supported format:

  • the file is a valid .keras model
  • the malicious operator is still a real serialized lambda
  • Keras still treats it as unsafe
  • existing scanner logic misses it because it only checks the layer graph

Notes

  • The included artifact is intentionally harmless and only writes a marker file.
  • This is a different primitive from a nested Lambda layer bypass: the model layers are benign and the payload is hidden in compile_config.
Downloads last month
20
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support